Bug 14941

Summary: test_shallow_submodules (bb.tests.fetch.GitShallowTest) failure because of git CVE fix
Product: [QA/Testing] Functional (self) Testing Reporter: Alexandre Belloni <alexandre.belloni>
Component: bitbake-selftestAssignee: Alexandre Belloni <alexandre.belloni>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: High CC: randy.macleod
Version: unspecified   
Target Milestone: 4.2 M1   
Hardware: x86   
OS: Multiple   
Whiteboard: backport all branches
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Alexandre Belloni 2022-10-19 21:53:39 UTC
======================================================================
ERROR: test_shallow_submodules (bb.tests.fetch.GitShallowTest)
----------------------------------------------------------------------
Traceback (most recent call last):
  File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/tests/fetch.py", line 1872, in test_shallow_submodules
    self.git('submodule add file://%s' % smdir, cwd=self.srcdir)
  File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/tests/fetch.py", line 423, in git
    return bb.process.run(cmd, cwd=cwd)[0]
  File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/process.py", line 189, in run
    raise ExecutionError(cmd, pipe.returncode, stdout, stderr)
bb.process.ExecutionError: Execution of 'git submodule add file:///tmp/bitbake-fetch-hp5nq_8y/gitsubmodule' failed with exit code 128:
Cloning into '/tmp/bitbake-fetch-hp5nq_8y/gitsource/gitsubmodule'...
fatal: transport 'file' not allowed
fatal: clone of 'file:///tmp/bitbake-fetch-hp5nq_8y/gitsubmodule' into submodule path '/tmp/bitbake-fetch-hp5nq_8y/gitsource/gitsubmodule' failed



file:// transport is disabled in git until there is a fix for CVE-2022-39253. The first impacted host is ubuntu 22.04 but all distributions will probably follow:
http://changelogs.ubuntu.com/changelogs/pool/main/g/git/git_2.34.1-1ubuntu1.5/changelog
https://git.launchpad.net/ubuntu/+source/git/tree/debian/patches/CVE-2022-39253-1.patch?h=applied/ubuntu/jammy-security
Comment 1 Randy MacLeod 2022-10-20 14:56:30 UTC
Alex has a work-around which has been applied to both dunfell and kirkstone. We need a better fix.

It seems that we should disable the test until the CVE is resolved properly.
Comment 2 Alexandre Belloni 2022-10-20 15:38:56 UTC
The actual patch breaking things is https://git.launchpad.net/ubuntu/+source/git/tree/debian/patches/CVE-2022-39253-11.patch?h=applied/ubuntu/jammy-security

And the fix seems to be using -c protocol.file.allow=always

I'll prepare a patch